(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)
Competency based placement focussed Education | Training | Research | Consultancy
Security researchers this week disclosed a sophisticated remote access trojan (RAT) campaign aimed specifically at software developers and DevOps engineers. The attackers distributed malicious installers for popular code editors and plug-ins via cloned download sites and poisoned search ads, quietly installing backdoors on high-value developer workstations. Once active, the RAT harvested SSH keys, repository credentials, and API tokens, providing attackers with a pathway into source code repositories and CI/CD pipelines. Organizations are being urged to verify download URLs, enforce least-privilege on developer machines, and monitor for unusual access to build systems. The campaign highlights how compromising builders upstream can yield far greater returns for attackers than targeting end users alone.
02-12-2025